Malicious PDF — malware analysis report

Static analysis result for SHA-256 04b2f45338fdd0c8…

MALICIOUS

PDF

18.3 KB Created: 2019-05-01 08:08:46 +01:00 Authoring application: mPDF 5.7
MD5: f6240c439984bf19add751f5630d3eb3 SHA-1: 9b93fb0f67eced5f9bd169a67861a6a13b26d070 SHA-256: 04b2f45338fdd0c8d85e753bf7e3cdabcafcab66011882a760b20ac14972f522
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the ML classifier also flagged the document as malicious, the specific intent appears to be SEO spam or a link farm rather than direct malware delivery. The embedded URLs themselves are not directly malicious but serve as a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9754

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/1730738738732734736/Ant-Ant-Ant-An-Insect-Chant-by-April-Pulley-Sayre.pdf
    • http://cefasfese.4pu.com/8734730736731737/Noodle-Man-the-Pasta-Superhero-The-Pasta-Superhero-by-April-Pulley-Sayre.pdf
    • http://cefasfese.4pu.com/1735736736737/Sixties-Going-on-Seventies-by-Nora-Sayre.pdf
    • http://cefasfese.4pu.com/8730730731739732/Moby-Dick-by-Lew-Sayre-Schwartz.pdf
    • http://cefasfese.4pu.com/2731732738730736/The-Buried-Book-by-D-M-Pulley.pdf
    • http://cefasfese.4pu.com/3738732739/The-Buried-Book-by-D-M-Pulley.pdf
    • http://cefasfese.4pu.com/6732732732/The-Bedlam-Stacks-by-Natasha-Pulley.pdf
    • http://cefasfese.4pu.com/1733730732730737/The-Watchmaker-of-Filigree-Street-by-Natasha-Pulley.pdf
    • http://cefasfese.4pu.com/1730734734732735730/Korean-War-Phase-4-25-January---21-April-1951-First-UN-Counteroffensive-and-22-April---8-July-1951-CCF-Spring-Offensive-by-John-Elsberg.pdf
    • http://cefasfese.4pu.com/9733738739735731/Proceedings-of-the-Second-April-Conference-of-University-Teachers-of-English-Cracow-1981-April-23-29-Papers-in-English-and-American-Literature-Cul-by-Irena-Kaluza.pdf
    • http://cefasfese.4pu.com/1738734736734738/His-Bear-s-Necessity-Return-To-Bear-Bluff-2-by-Harmony-Raines.pdf
    • http://cefasfese.4pu.com/2735733738738739/The-Little-Bear-and-the-Big-Bear-A-story-designed-to-help-teach-children-how-to-deal-with-frustration-anxiety-and-anger-by-Monica-Dumont.pdf
    • http://cefasfese.4pu.com/9732732733738738/The-Witness-and-the-Bear-Bear-Valley-Shifters-1-by-T-S-Joyce.pdf
    • http://cefasfese.4pu.com/2732736733734730/Bear-The-Heat-Bear-Instincts-1-by-Catherine-Vale.pdf
    • http://cefasfese.4pu.com/2737737732739/A-Visitor-for-Bear-Bear-and-Mouse-1-by-Bonny-Becker.pdf
    • http://cefasfese.4pu.com/8730738738731731/Little-Brown-Bear-Plays-in-the-Snow-Little-Brown-Bear-Series-by-Claude-Lebrun.pdf
    • http://cefasfese.4pu.com/3732734732738/Manifestation-Wolverine-The-Collected-Poetry-of-Ray-Young-Bear-by-Ray-Young-Bear.pdf
    • http://cefasfese.4pu.com/2736733730731/Sleepside-The-Collected-Fantasies-of-Greg-Bear-by-Greg-Bear.pdf
    • http://cefasfese.4pu.com/9732732734735735/Bear-Valley-Valentine-Bear-Valley-Shifters-5-5-by-T-S-Joyce.pdf
    • http://cefasfese.4pu.com/4735735733734734/Puck-Bear-Brides-Complete-Series-Puck-Bear-Brides-1-4-by-Anya-Nowlan.pdf